Build a board-ready risk heatmap in minutes — free, no account required

Open tool

Article 15

UpcomingConditional timing

Ensure High-Risk AI Accuracy, Robustness and Cybersecurity

Applies to Provider; High-Risk AI.

Actors
Provider
AI class
High-Risk AI
Themes
Security & ResilienceRisk & Assurance

Tracker Guidance

Design and develop each high-risk AI system to achieve an appropriate level of accuracy, robustness and cybersecurity throughout its lifecycle, taking account of the system's intended purpose and relevant risks.

Official text

Article 15Official source
1. High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle. 2. To address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies. 3. The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use. 4. High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard. The robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans. High-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures. [Excerpt - see official source for complete provision]

Excerpt stored at a complete legal-unit boundary. See the official source for the full provision.

Timing depends on the system

  • 2 Dec 2027Article 6(2) / Annex III high-risk AI
  • 2 Aug 2028Article 6(1) / Annex I Section A high-risk AI
  • 2 Dec 2027Pre-existing Annex III high-risk AI type/model first placed on the market or put into service before 2027-12-02
  • 2 Aug 2028Pre-existing Article 6(1) / Annex I high-risk AI type/model first placed on the market or put into service before 2028-08-02
  • 2 Aug 2030Pre-existing high-risk AI intended to be used by public authorities

Sub-obligations

These are independently assessable parts of the parent requirement.

  1. Article 15(1)-(3)

    Upcoming

    Define, Validate and Declare Appropriate Accuracy Levels and Metrics

    Tracker Guidance

    Identify and use appropriate accuracy levels and metrics for the high-risk AI system and state the relevant accuracy metrics and levels in the accompanying instructions for use.

    Official text

    Article 15(1)-(3)Official source
    1. High-risk AI systems shall be designed and developed in such a way that they achieve an appropriate level of accuracy, robustness, and cybersecurity, and that they perform consistently in those respects throughout their lifecycle. 2. To address the technical aspects of how to measure the appropriate levels of accuracy and robustness set out in paragraph 1 and any other relevant performance metrics, the Commission shall, in cooperation with relevant stakeholders and organisations such as metrology and benchmarking authorities, encourage, as appropriate, the development of benchmarks and measurement methodologies. 3. The levels of accuracy and the relevant accuracy metrics of high-risk AI systems shall be declared in the accompanying instructions of use.
  2. Article 15(4)

    Upcoming

    Design High-Risk AI for Resilience to Errors, Faults and Inconsistencies

    Tracker Guidance

    Design the high-risk AI system to be as resilient as possible to errors, faults and inconsistencies that may occur within the system or its operating environment. Use appropriate technical and organisational measures, including redundancy or fail-safe measures where relevant, and address harmful feedback loops in systems that continue learning.

    Official text

    Article 15(4)Official source
    4. High-risk AI systems shall be as resilient as possible regarding errors, faults or inconsistencies that may occur within the system or the environment in which the system operates, in particular due to their interaction with natural persons or other systems. Technical and organisational measures shall be taken in this regard. The robustness of high-risk AI systems may be achieved through technical redundancy solutions, which may include backup or fail-safe plans. High-risk AI systems that continue to learn after being placed on the market or put into service shall be developed in such a way as to eliminate or reduce as far as possible the risk of possibly biased outputs influencing input for future operations (feedback loops), and as to ensure that any such feedback loops are duly addressed with appropriate mitigation measures.
  3. Article 15(5); Article 42(3)

    Upcoming

    Protect High-Risk AI Against Cybersecurity and AI-Specific Attacks

    Tracker Guidance

    Apply cybersecurity measures appropriate to the risks and circumstances of the high-risk AI system, including where relevant measures addressing data poisoning, model poisoning, adversarial examples or model evasion, confidentiality attacks and model flaws. Where the system falls within Regulation (EU) 2024/2847 and satisfies the conditions in Article 12(1) of that Regulation, Article 42(3) of the AI Act provides a presumption of compliance with the AI Act's Article 15 cybersecurity requirements.

    Official text

    Article 15(5)Official source
    5. High-risk AI systems shall be resilient against attempts by unauthorised third parties to alter their use, outputs or performance by exploiting system vulnerabilities. The technical solutions aiming to ensure the cybersecurity of high-risk AI systems shall be appropriate to the relevant circumstances and the risks. The technical solutions to address AI specific vulnerabilities shall include, where appropriate, measures to prevent, detect, respond to, resolve and control for attacks trying to manipulate the training data set (data poisoning), or pre-trained components used in training (model poisoning), inputs designed to cause the AI model to make a mistake (adversarial examples or model evasion), confidentiality attacks or model flaws.
    Article 42(3)Official source
    3. Where high-risk AI systems fall within the scope of Regulation (EU) 2024/2847 and the conditions laid down in Article 12(1) of that Regulation are fulfilled, such systems shall be deemed to comply with the cybersecurity requirements set out in Article 15 of this Regulation.

Recognized by G2 as a Leader

Trusted by customers and rated highly across all categories

Article 15: Ensure High-Risk AI Accuracy, Robustness and Cybersecurity | EU AI Act Library